๐Ÿ” CVE Alert

CVE-2026-9066

UNKNOWN 0.0

WP Compress < 7.10.04 - Reflected XSS via test_zone

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to build the URLs of JavaScript files emitted on the page, leading to Reflected XSS. When a visitor follows a crafted link, the WP Compress WordPress plugin before 7.10.04's loader injects script elements pointing to an attacker-controlled origin, which lets the attacker execute arbitrary JavaScript in the visitor's session on the target site.

Vendor unknown
Product wp compress
Published Jul 23, 2026
Stay Ahead of the Next One

Get instant alerts for unknown wp compress

Be the first to know when new unknown vulnerabilities affecting unknown wp compress are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / WP Compress
0 < 7.10.04

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/133e2ca0-8cde-4b59-b680-0ddf95004625/

Credits

Lubin Regnault WPScan